First published: Mon Jan 06 2025(Updated: )
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
Credit: security@openvpn.net
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVPN | <3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8474 is classified as a medium-severity vulnerability.
To resolve CVE-2024-8474, upgrade OpenVPN Connect to version 3.5.0 or higher.
CVE-2024-8474 exposes the configuration profile's clear-text private key in the application log.
CVE-2024-8474 affects users of OpenVPN Connect prior to version 3.5.0.
An unauthorized actor can use the exposed private key to decrypt VPN traffic.